Privacy Policy for CradleCue
Effective date: February 12, 2026 | Last updated: February 12, 2026
This Privacy Policy explains how CradleCue ("CradleCue", "we", "us", or "our") collects, uses, shares, and protects information when you use the CradleCue mobile app, related services, and website at https://cradlecue.com.
By using CradleCue, you agree to this Privacy Policy.
1. Scope
This policy applies to:
- The CradleCue iOS app and watch features
- Our backend services and APIs
- Our website and support pages
This policy does not apply to third-party services we do not control, including Apple, Google, and Amazon Web Services pages you access separately.
2. Information We Collect
A. Account and authentication data
Depending on how you sign in, we may collect:
- Email address
- Password (stored as a one-way hash, not plain text)
- Full name (if provided)
- Authentication provider (
email,Google, orApple) - Provider user ID and linked-provider metadata
- Account timestamps (created/login times)
B. Baby profile data
You provide baby profile details such as:
- Baby name
- Birth date
- Optional nicknames
- Optional baby profile photo
C. Baby activity and health log data
You create event records in the app, including:
- Feeding and bottle events (amount/unit, side, timing, notes)
- Sleep events (start/end, notes)
- Diaper events
- Pumping events
- Medication logs and medication profiles
- Temperature logs
- Skin condition logs
- Notes
- Event metadata (timestamps, source, collaborator attribution)
D. Sharing and collaboration data
If you share access, we process:
- Invite target email
- Permission roles (
owner,editor,viewer) - Sharing metadata (who granted access, invite/share status, timestamps)
E. Photos and uploads
If you choose to add photos, we process:
- Optional profile photos
- Optional event photos (for supported event types)
- Upload/download metadata needed to generate secure temporary URLs
F. Notification and device data
To support sync and notifications, we may process:
- Push token
- App-generated device ID
- Platform/environment metadata
G. Technical and security logs
We may collect limited technical data for operations and security, such as:
- API request metadata (for example, route, timestamp, and source IP from infrastructure logs)
- Authentication/security events
- Error diagnostics
H. Data from Google or Apple sign-in
If you use Google or Apple sign-in (where available), we receive identity information necessary for authentication, such as your verified email, provider subject ID, and optional profile name.
We do not request Gmail, Google Drive, Calendar, or similar non-authentication scopes.
3. How We Use Information
We use your information to:
- Create and secure your account
- Authenticate you and keep you signed in
- Store and sync baby tracking data across your devices
- Enable sharing with invited caregivers
- Deliver notifications and reminders
- Provide charts, summaries, exports, and app functionality
- Protect against fraud, abuse, and unauthorized access
- Maintain, debug, and improve service reliability
- Comply with legal obligations
We do not use baby activity data for third-party ad targeting.
4. Legal Bases (where applicable)
If laws like GDPR apply, our legal bases generally include:
- Performance of a contract (providing the app and requested features)
- Legitimate interests (security, reliability, fraud prevention)
- Consent (for optional notifications or permissions)
- Legal obligations (compliance and lawful requests)
5. How We Share Information
We may share information:
- With caregivers you invite or authorize in-app
- With service providers that process data for us (for example, cloud hosting and infrastructure)
- With identity providers when you choose provider sign-in (Apple/Google)
- When required by law, regulation, or legal process
- To protect rights, safety, and security of users or the public
We do not sell personal information.
6. Third-Party Services
CradleCue uses third-party infrastructure and platform services, including:
- Apple services (iOS, App Intents, notifications, and sign-in where used)
- Google sign-in services (if enabled and selected by you)
- Amazon Web Services for backend APIs, storage, and logging
Those providers have their own privacy terms.
7. Data Retention
We retain data for as long as needed to provide the service and for legitimate operational/legal reasons.
Examples from current service behavior:
- Account/auth records: retained while account is active and as needed for security/compliance
- Deleted event tombstones: may be retained for up to about 90 days for sync integrity before cleanup
- Push token registrations: include a rolling expiration window (about 60 days unless refreshed)
- Pending invites: expire automatically (about 30 days)
- Share links: short-lived expiration (about 7 days)
- Verification/reset tokens: short-lived security expiration windows
When you request deletion, we remove or de-identify data within reasonable operational timelines, except where retention is legally required.
8. Your Choices and Rights
Depending on where you live, you may have rights to:
- Access personal information
- Correct inaccurate information
- Request deletion
- Export your data (for example via in-app PDF/CSV exports)
- Object to or limit certain processing
- Appeal denied requests (where legally required)
You can also:
- Manage notification permissions in iOS settings
- Remove shared access for caregivers
- Delete baby records/events in-app (subject to account role permissions)
For privacy requests, contact: privacy@cradlecue.com
9. Children's Privacy
CradleCue is intended for parents, guardians, and caregivers, not for direct use by children.
The app may store child-related information that adult users enter. We process that information only to provide requested family tracking functionality.
10. Security
We use administrative, technical, and organizational safeguards designed to protect information, including authenticated APIs, access controls, and secure transport.
No method of storage or transmission is 100% secure, so we cannot guarantee absolute security.
11. International Transfers
If you access CradleCue from outside the country where our infrastructure is hosted, your information may be processed in other jurisdictions where privacy laws may differ.
12. Changes to This Policy
We may update this Privacy Policy periodically. We will post the updated version on this page and update the "Last updated" date.
Material changes may also be communicated in-app or by email when required.
13. Contact Us
CradleCueDelaware, United States
General support: support@cradlecue.com
Privacy requests: privacy@cradlecue.com